Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's a completly bogus excuse. The question wasn't why you're releasing it publicly, but why you haven't made any attempt to contact the company beforehand, which you seem to have had a year to do.

Edit: The only reasons I can think of are laziness or just plain not giving a shit about responsible disclosure.



In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in the past when faced with intractable, deep-seated defects in a product, so it wouldn't be unexpected or unreasonable to assume.

All the notification would be is a courtesy, allowing them time to start designing and marketing a new product, instead of having the market get handed to their competitors when hotels suddenly have to start replacing their locks with less-flawed ones. And I'm not sure a company that produced a flawed products deserves that.


> In order so that they could do ... what, exactly?

They can either say "Thanks for telling us. We're fixing the locks. There a X thousand locks, and we expect it to take Y weeks to fix them Please consider delaying release of this informtion until after then" - in which case he's done the responsible thing and can chose what to do.

Or they can say "We know, there's nothing we can do, don't tell anyone" in which case he's done the responsible thing and can decide what to do.


Or they can drag him through the courts to try to prevent the release of the information.


"Someone might sue me for doing the right thing" is a pretty thin excuse. There's a reason it's called "doing the right thing" instead of "doing what's easiest for you."

Say I'm a lawyer, and I find out that in order to help a client of mine I have to present evidence that's extremely embarrassing to a close friend of mine. I'm am professionally and ethically obligated to present that evidence.

Now, security professionals don't have, and probably shouldn't have, fiduciary responsibilities like that. However, industries set up codes of ethics for their members precisely because there's a difference between "what's best for me right now" and "what's the right thing to do."

If the idea is to embarrass the industry into fixing these problems, an article in Forbes does a pretty good job of that.


> what, exactly?

They could plug the access holes, with custom pentalobe screws. That's an under a dollar per lock fix.


So, that's more than a million dollars more than NYSE:UTX's gross profits for the last quarter, and ~1/4 of their gross revenue over the same quarter. No, I don't think they were going to do that.


Financial reports are typically in 1000s of dollars - UTX's net reported in 03/2012 were $330 million USD.

edit: source is http://finance.yahoo.com/q/is?s=UTX ('All numbers in thousands' in upper right of the statement). Easy mistake! I just happened to be passingly familiar with United Technologies, which is a large diversified industrial conglomerate that includes Carrier (A/C systems), Sikorsky (helicopters), and Pratt & Whitney (aircraft engines) among other subsidiaries.


URL? I got mine from Google Finance, but only quickly eyeballed it; it's very likely you're right.


C'mon. It's well under a dollar. And that's a 10 second idea, I'm sure there are other options.

(edit) That's not even considering that this cost can be carried by the hotels. I'm sure they can cough up $500 to secure their facilities.

--

Please don't tell me that you, of all people on HN, think that there's no need for a private disclosure on this guy's part?


It's way more than a dollar. How many locks could one technician replace/fix in an hour, and what's their hourly rate?

"Me of all people"? Am I a spokesperson for "Responsible disclosure" now?

I would have notified the vendor ASAP, and I might not have put the vendor name into the talk at all. But that's me, and I am super conservative about this stuff. Lots of very reputable security people would do exactly what Cody did.


Not in bulk. Hotel technicians install and service locks, I'm sure they'll manage to screw a bolt into a hole. They are salaried.

"You" as a "sensible security guy". Or at least that was my impression of you based on what you post here.


For clarification: lots of "very reputable security people" can also be total dicks. Hacker elitism does not encourage thoughtfulness.


As an industry we are a pretty awful people.


Now the device used to break into the rooms costs $57 instead of $50.

Cool story, bro.


...so that Fortune could publish an article saying he followed industry-standard guidelines of responsible disclosure, so that non-techies wouldn't get further ammo to say "there ought to be a law against this."


He hasn't even gone to the point of no return yet. The vendor's competitors -- assuming they aren't similarly vulnerable -- can point this news article out in their marketing literature.

The company can probably come up with a solution faster than a brand new third party can generate all of this guy's work.


> the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible

While that may be "profit-maximizing", it's not necessarily "rational". I'd sooner call it "short-sighted", "single-minded" or "primitive".

It might be "rational" from the pov of such a corporation as a single organism but it's not from the view of the humans that make up its arms, legs and eyes. And they live in the same society as the hotel owners and hotel guests, unless they choose not to, but it's getting harder and harder to make that choice thanks to people like Daeken.

And about the corporate organism? In its own competitive environment, it's got a primitive predatory intelligence, roughly comparable to that of a big spider (its products may be clever and complex, but its behaviour is not). If that's "rationality", we should probably consider setting the bar a bit higher for ourselves.


In order so that they could do ... what, exactly?

There may be lots of things the vendor could do. They could contact their customers so the hotels have a chance to consider their options. There is a good chance the vendor knows the protocol better than the guy who reverse engineered it; maybe there is a kill-code that they could give their hotels.

when hotels suddenly have to start replacing their locks with less-flawed ones. And I'm not sure a company that produced a flawed products deserves that.

You don't know that other products are better. In fact, he's said that there are other products he hasn't tested but still have the port. Maybe they are even easier to hack.

The company is going to have to deal with bad publicity regardless. It's just that know hotel managers are going to be in panic mode because of this guy is giving out all the directions so anyone can make their own skeleton key.


But imagine, if he had told them a year ago, perhaps the locks would be mostly replaced with a fixed version by now! I think it's unbelievable that he wouldn't disclose this information because he "just knows" they wouldn't do anything. He's not a damn mind reader. Hell, he might even be right, but you've still got to give the company the chance.


May I suggest you read up on some more stories about disclosure in the security industry. There have been many, many people before him that wanted to give them that chance and they've been sorely disappointed, time and time again. Hell you don't even know if Daeken maybe gone through this route from, you know, his own experience?

Fool me once, shame on me, fool me twice, and I'm supposed to be a damn mind reader?!

Also see: http://en.wikipedia.org/wiki/The_Scorpion_and_the_Frog


There is the possibility of being dragged through a lawsuit, and/or the company one works through being dragged through a lawsuit. I don't know if that is applicable here, but I have been involved in a responsible disclosure where I gave the information to a colleague, who then disclosed to the company, and the company then sent a letter threatening a lawsuit, whereas my colleague nearly got fired (the fact that he didn't was the one time I can remember the union stepping up to do something useful by defending him). Whether or not such lawsuits would hold merit, they'd be expensive for all involved, and lots of listed companies are more than happy to put the lawyers on you for invalid reasons.


People do use the legal system for suppression of free speech, to chill censors. There are also lawyers who will take issues like that pro bono. Google up the Popehat Symbol for some examples.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: